Description
Processing untrusted XML without schema validation can allow structures or values the application does not expect. Avoid explicitly disabling validation with settings such as XmlReaderSettings.ValidationType = ValidationType.None at a security boundary.
Potential impact
- Invalid XML can reach business logic and lead to authorization bypass, data manipulation, or denial of service through exceptions.
Remediation
Register a trusted schema and use ValidationType.Schema. If external entities are not needed, also set DtdProcessing.Prohibit and XmlResolver = null. Validation occurs as the reader consumes the document, so read it to completion and do not pass data that fails validation to business logic.
Examples
Before
csharp
var settings = new XmlReaderSettings
{
ValidationType = ValidationType.None
};
using var reader = XmlReader.Create(stream, settings);
After
csharp
var settings = new XmlReaderSettings
{
ValidationType = ValidationType.Schema,
DtdProcessing = DtdProcessing.Prohibit,
XmlResolver = null
};
settings.Schemas.Add("urn:example", "schema.xsd");
using var reader = XmlReader.Create(stream, settings);
Explanation:
- Before: Parsing security-sensitive XML without schema validation can let invalid or unexpected data reach application logic.
- After: Configure
XmlReaderSettingswithValidationType.Schemaand a trusted schema set before parsing untrusted XML.